This advisory has been withdrawn because it is a duplicate of GHSA-74pj-6g7r-j55c. This link is maintained to preserve external references.
SiYuan before v3.7.4 contains an information disclosure vulnerability in the /api/notebook/getNotebookInfo endpoint that returns notebook metadata without authorization checks. Attackers can read notebook names, document counts, sizes, and timestamps for closed or non-published notebooks that should be hidden from readers.
{
"cwe_ids": [
"CWE-862"
],
"github_reviewed": true,
"github_reviewed_at": "2026-09-08T17:54:00Z",
"nvd_published_at": "2026-08-12T20:17:50Z",
"severity": "MODERATE"
}